First published: Fri Mar 15 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire Web Player | =3.3 | |
TIBCO Spotfire Web Player | =3.3.2 | |
TIBCO Spotfire Web Player | =4.0 | |
TIBCO Spotfire Web Player | =4.0.1 | |
TIBCO Spotfire Web Player | =4.0.2 | |
TIBCO Spotfire Web Player | =4.5.0 | |
TIBCO Spotfire Web Player | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2372 has been classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2013-2372, upgrade TIBCO Spotfire Web Player to version 3.3.3, 4.0.3, 4.5.1, or 5.0.1 or later.
CVE-2013-2372 affects TIBCO Spotfire Web Player versions 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1.
CVE-2013-2372 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web script or HTML.
Any organization using vulnerable versions of TIBCO Spotfire Web Player is at risk due to CVE-2013-2372.